The account's environment and the shell's contributions (hq ADR 0203, ADR 0204, to-be 41 WP2) #260

Merged
mesh-admin merged 3 commits from feat/the-shell-and-its-environment into main 2026-10-04 08:49:35 +00:00
Contributor

hq to-be 41 WP2.

  • New seats: node-environment (no verbs) and node-login-shell (verb execute). A module declaring login-shell is refused (ADR 0204).

  • New manifest fields:

    • environment: variables and path entries placed at the start or end;
    • shell: code for zsh/bash/fish in a first/normal/last slot.

    Both are parsed strictly, and a value carrying $ (other than ${machine:…}), a quote, a backslash or a line break is refused.

  • Composition fills, in the claiming holder's file contents:

    • ${environment:posix}: exports, plus PATH entries added only if missing, so sourcing twice changes nothing;
    • ${environment:systemd}: environment.d syntax;
    • ${shell:<shell>:<slot>}: filled last and never re-scanned, so contributed ${…} code passes through byte for byte.
  • Refused:

    • a variable set by two modules on one node;
    • a placeholder in a module that does not claim the seat (at the catalogue check and at composition);
    • an unknown placeholder key.

Tests: internal/catalogue/environment_into_test.go. The POSIX rendering is sourced twice by sh, and the systemd rendering is run through the real environment-d generator where one is installed. The full suite passes with Postgres and NATS, except TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves, which already fails on main. module check over the catalogue branch of the same name passes all 73 manifests.

hq to-be 41 WP2. - **New seats:** `node-environment` (no verbs) and `node-login-shell` (verb `execute`). A module declaring `login-shell` is refused (ADR 0204). - **New manifest fields:** - `environment`: `variables` and `path` entries placed at the `start` or `end`; - `shell`: code for zsh/bash/fish in a `first`/`normal`/`last` slot. Both are parsed strictly, and a value carrying `$` (other than `${machine:…}`), a quote, a backslash or a line break is refused. - **Composition fills, in the claiming holder's file contents:** - `${environment:posix}`: exports, plus PATH entries added only if missing, so sourcing twice changes nothing; - `${environment:systemd}`: environment.d syntax; - `${shell:<shell>:<slot>}`: filled last and never re-scanned, so contributed `${…}` code passes through byte for byte. - **Refused:** - a variable set by two modules on one node; - a placeholder in a module that does not claim the seat (at the catalogue check and at composition); - an unknown placeholder key. Tests: `internal/catalogue/environment_into_test.go`. The POSIX rendering is sourced twice by `sh`, and the systemd rendering is run through the real environment-d generator where one is installed. The full suite passes with Postgres and NATS, except `TestTheResolverIsToldEveryMachineOnTheNetworkAndToldAgainWhenOneLeaves`, which already fails on main. `module check` over the catalogue branch of the same name passes all 73 manifests.
mesh-admin added 3 commits 2026-10-04 08:33:08 +00:00
node-environment says which module writes the account's environment; node-login-shell
replaces the module-declared login-shell, so a second shell claims it rather than
declaring a rival, and execute is the mesh's contract. login-shell is refused as a
module's seat name. Seeded into a live store by the existing additive seeding.
A module contributes environment variables, PATH entries and shell code in named slots;
the holder of the matching seat places them with ${environment:posix|systemd} and
${shell:<shell>:<slot>}. Rendered in module order with a naming line per contribution,
PATH entries added only when missing, machine facts resolved first. A variable two
modules set, or a placeholder outside its seat's holder, is refused at parse (the
catalogue check) and at composition. Filled after every other placeholder pass, so no
scanner ever reads a shell's own ${...}.
mesh-admin merged commit d8a0238e02 into main 2026-10-04 08:49:35 +00:00
mesh-admin deleted branch feat/the-shell-and-its-environment 2026-10-04 08:49:35 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#260